Application Security DevSecOps Specialist
Brasov, RO Cluj, RO Sibiu, RO Iasi, RO Timisoara, RO Bucuresti, RO Novi Sad, RS Remote, RO Serbia remote, RS
Who we are
NTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.
What you'll be doing
- Implement security measures within CI/CD pipelines to ensure secure software delivery.
- Static Application Security Testing (SAST) tools for analysing source code or binaries.
- Dynamic Application Security Testing (DAST) tools for identifying vulnerabilities in running applications.
- Software Composition Analysis (SCA) tools to detect vulnerabilities in open-source libraries and third-party components.
- Secret scanning to prevent accidental inclusion of sensitive information like API keys or passwords.
- Container scanning to analyse container images and runtime environments for vulnerabilities and misconfigurations.
- Conduct code security reviews and triage security findings.
- Collaborate with developers to fix identified vulnerabilities and ensure secure coding practices.
- Perform API security testing for standalone APIs not integrated within applications.
- Manage security testing automation processes.
- Integrate security testing tools with organizational systems such as CMDB, ticketing systems, and reporting platforms.
- Maintain tool certifications and stay updated with the latest capabilities and advancements.
- Provide clear and actionable communication of findings to enable informed, prioritised actions.
- Deliver detailed assessment reports with remediation recommendations aligned to risk severity.
- Present findings to both technical and non-technical stakeholders, including executive leadership.
- Maintain comprehensive documentation of security assessments, findings, and remediation tracking.
- Work closely with development teams to integrate security seamlessly into their workflows.
- Train developers on secure coding practices and the use of security tools.
- Evaluate and implement AI-powered application security testing tools, ensuring validation of AI-generated findings by human experts.
- Maintain awareness of AI-powered tools' limitations and compliance requirements.
- Enhance the speed and reliability of secure code delivery.
- Reduce vulnerabilities and improve the overall security posture of applications.
- Ensure compliance with industry standards such as OWASP Top 10, CIS Benchmarks, and secure coding practices .
- Work closely with Security Design Engineers to implement designs within frameworks defined by Security Architects.
What you'll bring along
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Minimum 3 – 5 years of experience in security testing tools and automation.
- Knowledge of DevSecOps practices and CI/CD pipeline integration.
- Familiarity with industry standards like OWASP, CIS Benchmarks, and secure coding guidelines.
- Strong collaboration and communication skills for working with developers and stakeholders.
- Excellent command of both spoken and written English
What’s in it for you
✔ New beginnings can be a challenge. We promise a smooth integration and a supportive mentor
✔ Pick your working style: choose from Remote, Hybrid or Office work opportunities
✔ Early bird or night owl? Our projects have different working hours to suit your needs
✔ Nobody is born an expert. Sharpen your tech skills with our sponsored certifications, trainings and top e-learning platforms
✔ We want you to stay healthy! Enjoy our Private Health Insurance – it’s custom-made for you
✔ A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School
✔ Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families
NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ancestry, age, sex, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic protected by law. We are committed to creating a diverse and inclusive environment for all employees.
Not the job for you? Perhaps you have a friend who would be a perfect fit. Send them this link!
Third parties fraudulently posing as NTT DATA recruiters
NTT DATA recruiters will never ask job seekers and candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties that may try to impersonate NTT DATA recruiters, either in writing or by phone, in an attempt to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will be associated with an @nttdata.com email address. NTT DATA will not use any non-NTT DATA or personal email domains (Gmail, Yahoo, etc.) or personal communication channels (WhatsApp, Facebook etc) at any time during the recruitment process. If you suspect any fraudulent activity, please contact us.
Job Segment:
Open Source, Testing, Computer Science, Developer, Technology, Security